net/packet: clear RX owner on VNET header error

Summary

CVECVE-2026-98233
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:10 UTC
Updated2026-10-06 09:18:10 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here.

Risk And Classification

EPSS: 0.002200000 probability, percentile 0.113620000 (date 2026-10-06)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 bb10a0084c03a94364aeec542beddc5d49b59f59 git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 b8c0cb3069058c2d67b5c7c833b2833381ecffdc git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 2daa618e7ff19eefcbda281bc4c5998c4140f9cf git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 23cd30498891d29a69ec9b75bd92f8a0f21f1342 git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 49a48a5aaf85fe69d2dc3fb334b4854fadf44e39 git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 805edbdcb8681da5f7ee43b3c3c809f7a8c31208 git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 693209a237fc548791cf402441db8b68d1da7d38 git Not specified
CNA Linux Linux affected 61fad6816fc10fb8793a925d5c1256d1c3db0cd2 33ff111d7ba3beb86e28938d6382bb5beabd865a git Not specified
CNA Linux Linux affected 2975472e042e0bbfeeabddc5023cb8c011ec5a07 git Not specified
CNA Linux Linux affected 6fb0e4385928900ccb8697748555b3f54bba5193 git Not specified
CNA Linux Linux affected 86137342fd4cf52882842aa8d1318b2661f08e8a git Not specified
CNA Linux Linux affected b06e4d3ed4044c2facf10a511d809f9aa29d960e git Not specified
CNA Linux Linux affected 4.14.175 4.15 semver Not specified
CNA Linux Linux affected 4.19.114 4.20 semver Not specified
CNA Linux Linux affected 5.4.29 5.5 semver Not specified
CNA Linux Linux affected 5.5.14 5.6 semver Not specified
CNA Linux Linux affected 5.6 Not specified
CNA Linux Linux unaffected 5.6 semver Not specified
CNA Linux Linux unaffected 5.10.271 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/2daa618e7ff19eefcbda281bc4c5998c4140f9cf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/23cd30498891d29a69ec9b75bd92f8a0f21f1342 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b8c0cb3069058c2d67b5c7c833b2833381ecffdc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/33ff111d7ba3beb86e28938d6382bb5beabd865a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bb10a0084c03a94364aeec542beddc5d49b59f59 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/805edbdcb8681da5f7ee43b3c3c809f7a8c31208 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/49a48a5aaf85fe69d2dc3fb334b4854fadf44e39 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/693209a237fc548791cf402441db8b68d1da7d38 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report